Prosecution Insights
Last updated: August 17, 2026
Application No. 19/175,980

IDENTIFICATION OF TYPOSQUAT DOMAIN VARIATIONS IN PASSIVE DOMAIN NAME SYSTEM (PDNS)

Non-Final OA §102§103
Filed
Apr 10, 2025
Priority
Nov 27, 2024 — provisional 63/726,160
Examiner
GYORFI, THOMAS A
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
Infoblox Inc.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
2y 1m
Est. Remaining
92%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
528 granted / 699 resolved
+17.5% vs TC avg
Strong +16% interview lift
Without
With
+16.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
12 currently pending
Career history
715
Total Applications
across all art units

Statute-Specific Performance

§101
9.5%
-30.5% vs TC avg
§103
52.3%
+12.3% vs TC avg
§102
21.0%
-19.0% vs TC avg
§112
7.9%
-32.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 699 resolved cases

Office Action

§102 §103
DETAILED ACTION Claims 1-20 are presented for examination. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 6/24/25 has been considered by the Examiner. Claim Rejections - 35 USC § 102 and 103 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-4, 8-10, 13-15, & 17-20 are rejected under 35 U.S.C. 102(a)(1) and 35 U.S.C. 102(a)(2) as anticipated by Lee (U.S. Patent Publication 2022/0377107) or, in the alternative, under 35 U.S.C. 103 as obvious over Lee in view of the Swype™ virtual keyboard, as evidenced by the Wikipedia article for “Swype” (hereinafter, “Swype Wiki”) and “Swype IOS FAQS” (hereinafter, “Swype FAQ”). Regarding claims 1, 17, and 20: Lee discloses a system [and corresponding method & computer program product] comprising: a processor (paragraph 0089) configured to: generate a plurality of candidate typosquat domains using a virtual keyboard (paragraph 0074: “During the setup phase, the checking list L is also provided to Swype image renderer 115. Swype image renderer 115 then renders Swype-like images for each of the domains in checking list L. A trained typo-squatting encoder ES, which is provided within typo-squatting detection module 130, is then configured to generate encodings for each of the rendered Swype-like images”; and paragraph 0080: “Concurrently, Swype image renderer 115 is configured to render the domain names from the set of DNS records 103 into a set of Swype-like images, IST_N. Typo-squatting detection module 130, which is provided with the trained typo-squatting encoder ES and the reference database DS is then configured to receive the set of Swype-like images, IST_N , from Swype image renderer 115.”); automatically classify a subset of the plurality of the candidate typosquat domains that each have been previously queried based on Domain Name System (DNS) logs to generate targeted candidate typosquat domains, wherein the classifying includes at least in part performing a Euclidean distance calculation using the virtual keyboard as a plane (paragraph 0080: “The trained typo-squatting encoder ES, then proceeds to encode each of the Swype-like images IST_N into their associated encodings eST_N . These encodings eST_N are then compared with encodings contained within reference database DS. If it is found that a Euclidean distance between an associated encoding eST_N and any encoding in the reference database DS is below a predetermined threshold; or in other embodiments, if there exists a cosine similarity between an associated encoding eST_N and any encoding in the reference database DS that is above a required matching threshold, module 130 will then classify that associated encoding eST_N as a typo-squatting phishing domain”; see also Figure 9 and paragraphs 0104-0105); and perform an action for one or more of the targeted candidate typosquat domains (paragraph 0115, including: “A similarity comparison of the encoding of the queried domain is then carried out with the encodings in database 1112 at step 1114. If the cosine similarity (or Euclidean distance) between the encoding of the queried domain and any of the encodings of domains in the dataset is more (or less in the case of Euclidean distance) than a particular threshold, the queried domain is then classified as a typo-squatting phishing domain and an alert with its “targeted” domain is then produced” [emphasis Examiner’s]; see also paragraphs 0041-0044 & 0083 regarding additional alert module functionality); and a memory coupled to the processor and configured to provide the processor with instructions (paragraphs 0088-0089). For purposes of the novelty rejection under 35 USC 102, the Examiner has construed Lee’s “Swype image renderer” (element 115 of Figure 1/element 900 of Figure 9) as a “virtual keyboard” under the broadest reasonable interpretation of the term as would be understood by a person of ordinary skill in the art, based primarily on Lee’s description of how it functions (paragraphs 0104-0105) as well as the fact that “Swype”, while not explicitly defined by Lee, appears to refer to the Swype™ virtual keyboard product which was a prior art virtual keyboard wherein the user-generated strokes between the individual keys, rather than the discrete presses, determine the word the user is trying to type (Swype Wiki, page 1, first paragraph: “Swype is a virtual keyboard for touchscreen smartphones and tablets originally developed by Swype Inc., founded in 2002, where the user enters words by sliding a finger or stylus from the first letter of a word to its last letter, lifting only between words.”; and Swype FAQ, page 2, “Can you tell me more about Swype?”). However, assuming arguendo that the “Swype image renderer” element disclosed by Lee were not a virtual keyboard per se, then it would have been immediately obvious prior to the effective filing date of the instant application for Lee to have used Swype™ (or a comparable virtual keyboard with gesture functionality: see Swype Wiki, page 5, “Competitors”) as the Swype image renderer of his invention, as these were clearly well-known options within the grasp of a person of ordinary skill in the art, with the added benefit that gesture-based virtual keyboards like Swype™ allow for faster input of text on a touchscreen device (Swype Wiki, pages 1-2, “Software”). Regarding claim 2 and 18: Lee further discloses wherein the plurality of candidate typosquat domains includes second level domains and subdomains (e.g. paragraphs 0077 & 0083). Regarding claim 3 and 19: Lee further discloses wherein the virtual keyboard includes a QWERTY format and/or a format for non-English languages (paragraph 0104; see also Swype FAQ, page 5, “How do I change my keyboard layout?” for non-English format support). Regarding claim 4: Lee further discloses wherein the virtual keyboard includes a QWERTY format (paragraph 0104), and wherein a Euclidean distance calculation is performed between a first candidate domain and a first authentic domain (paragraphs 0113-0115). Regarding claim 8: Lee further discloses wherein the processor is further configured to: send the targeted candidate typosquat domains to a DNS threat feed (paragraphs 0041-0044). Regarding claim 9: Lee further discloses wherein the processor is further configured to: automatically generate a malicious typosquat domains feed for typosquat domains classified as malicious (paragraphs 0041-0044 and 0083). Regarding claim 10: Lee further discloses wherein the processor is further configured to: automatically add typosquat domains classified as malicious to a domain block list (see the blacklist at paragraphs 0130-0136). Regarding claim 13: Lee further discloses wherein the processor is further configured to: identify regular typosquats, exact label typosquats, combosquats, and/or combo typosquats from the targeted candidate typosquat domains (at least regular typosquats at e.g. paragraph 0105; see also paragraph 0008 including Table 1 for more examples). Regarding claim 14: Lee further discloses wherein the processor is further configured to: filter the targeted candidate typosquat domains using one or more filters to reduce false positives (paragraphs 0021, 0082, and 0124). Regarding claim 15: Lee further discloses wherein the processor is further configured to: receive input of one or more domains associated with an entity to use a domain seed list (paragraph 0125: “A list of keywords that are typically used to tempt people into clicking on sites is initially generated”); filter the targeted candidate typosquat domains using one or more filters to reduce false positives, wherein the filtering includes one or more of the following: word-based filtering for contextual meaning, DNS fingerprint-based filtering, and/or textual analysis-based filtering (Ibid: “When a set of DNS records are provided, keyword filter will filter away records whose domain names do not have at least one of the keywords in the list K at step 1402”); and identify one or more malicious typosquat domains from the targeted candidate typosquat domains (paragraph 0126: “Suspicious domain names (i.e. domain names flagged by neural network 1404 to be possible general phishing domains) obtained from step 1404 are then used…”). Claims 5, 6, 11, 12, & 16 are rejected under 35 U.S.C. 103 as being unpatentable over Lee [alone or in view of Swype] as applied to claim 1 above, and further in view of Szurdi (U.S. Patent Publication 2025/0112935). Regarding claim 5: Lee does not disclose wherein the DNS logs include passive DNS (pDNS) including raw DNS logs and/or zone archive files. However, Szurdi discloses a related invention for detecting malicious domain names including typosquat candidates (e.g. Abstract, and paragraph 0137) wherein this limitation is taught (e.g. paragraphs 0020, 0037, 0065, 0083, 0103, & 0106; more detail regarding pDNS at paragraphs 0150-0158; more detail regarding zone information at paragraph 0073). It would have been obvious prior to the effective filing date of the instant application for Lee to have used passive DNS as the source for his DNS records from which he determines candidate typosquats, as pDNS records are usable to specifically look for domains that exhibit patterns that are not consistent with stockpiled or otherwise malicious domains or would result in a false positive significantly impacting customers (Szurdi, paragraph 0119). Regarding claim 6: Lee further discloses wherein the processor is further configured to: automatically classify a subset of a plurality of candidate typosquat candidates that each have been previously queried based on Domain Name System (DNS) logs to generate targeted candidate typosquat candidates (e.g. paragraphs 0068, 0073, & 0080), but it is not clear if Lee’s invention specifically determines if they are combo typosquatting candidates. However, Szurdi discloses a related invention for detecting malicious domain names including typosquat candidates (e.g. Abstract, and paragraph 0137) wherein multiple variants of domain squatting are all equally detectable by that invention (Ibid: “0: no squatting, 1: typosquatting, 2: combosquatting, 3: levelsquatting, 4: soundsquatting”). It would have been obvious prior to the effective filing date of the instant application for Lee to detect combosquatting in addition to regular typosquatting, as these variants were all known options for a person of ordinary skill in the art to look for, given an invention that can detect malicious domain names that resemble legitimate domains. If Lee detecting a typosquatting candidate that conforms to Szurdi’s definition of a combosquat would lead to success, then it would be the result not of innovation but of ordinary skill and common sense (see also Lee, paragraph 0008 including Table 1, which appears to contain examples of combosquatting domain names – though not explicitly designated by Lee as such – that the Lee invention can nevertheless recognize and detect). Regarding claim 11: Lee further discloses wherein the processor is further configured to: automatically add typosquat domains classified as malicious to a domain block list for the targeted candidate typosquat domains (paragraphs 0130-0136), but Lee does not explicitly disclose that this is done in response to determining that the typosquat domains are not registered to a verified entity. However, Szurdi discloses a related invention for detecting malicious domain names including typosquat candidates (e.g. Abstract, and paragraph 0137) wherein this limitation is taught (Szurdi, paragraph 0062, including: “Communication module 225 is configured to query third party service(s) for information pertaining to the domain classifications (e.g., services that expose information/classifications for signatures/hashes of domains, registrants of domains, etc., such as third-party scores or assessments of maliciousness of a particular domain or a domain registrant, a community-based score, assessment, or reputation pertaining to domains or applications, a blacklist for domains, and/or a whitelist for domains, applications, or other certain types of network traffic, etc.)” [emphasis Examiner’s]; see also paragraphs 0038, 0068, 0075, 0104, & 0171-0172 regarding using a WHOIS database query to determine information about the registrant of a domain name as part of the determination process for identifying a malicious domain). It would have been obvious prior to the effective filing date of the instant application for Lee to use registrant information to determine if a domain name was registered to a legitimate entity as part of his process for identifying typosquat domains, as knowing who the entity is that registered a given domain name candidate can be used in reputation-based heuristics to determine if the domain name is malicious (Szurdi, paragraph 0075). Regarding claim 12: Lee further discloses wherein the processor is further configured to: automatically add typosquat domains classified as malicious to a domain block list for each of the targeted candidate typosquat domains that satisfy at least the following criteria: (2) exceed a threshold probability of typosquat based on a spatial cost calculation using a Euclidean distance between a candidate domain and authentic domain of the virtual keyboard as the plane (paragraphs 0074, 0080, 0115, and 0130-0136). Lee does not explicitly disclose the criteria of the registrant of the candidate domain being a verified entity. However, Szurdi discloses a related invention for detecting malicious domain names including typosquat candidates (e.g. Abstract, and paragraph 0137) wherein this limitation is taught (Szurdi, paragraph 0062: “Communication module 225 is configured to query third party service(s) for information pertaining to the domain classifications (e.g., services that expose information/classifications for signatures/hashes of domains, registrants of domains, etc., such as third-party scores or assessments of maliciousness of a particular domain or a domain registrant, a community-based score, assessment, or reputation pertaining to domains or applications, a blacklist for domains, and/or a whitelist for domains, applications, or other certain types of network traffic, etc.)” [emphasis Examiner’s]; see also paragraphs 0038, 0068, 0075, 0104, & 0171-0172 regarding using a WHOIS database query to determine information about the registrant of a domain name as part of the determination process for identifying a malicious domain). It would have been obvious prior to the effective filing date of the instant application for Lee to use registrant information to determine if a domain name was registered to a legitimate entity as part of his process for identifying typosquat domains, as knowing who the entity that registered a given domain name candidate can be used in reputation-based heuristics to determine if the domain name is malicious (Szurdi, paragraph 0075). Regarding claim 16: Lee does not explicitly disclose wherein the processor is further configured to: filter at least one of the targeted candidate typosquat domains using SAN SSL certificates to determine whether the at least one targeted candidate typosquat domain belongs to a legitimate organization, and if so, filter out the at least one candidate typosquat domain. However, Szurdi discloses a related invention for detecting malicious domain names including typosquat candidates (e.g. Abstract, and paragraph 0137) wherein this limitation is taught (paragraph 0071: “In addition, for services running on SSL, the system obtains and stores certificates, which can be compared directly or used to generate features.”; SAN [Subject Alternative Name] as part of the certificate at paragraphs 0140-0141 and the subsequent table on page 16, “Domain name count: The number of domains in the subject alternative name and common name fields”; see also e.g. paragraphs 0020, 0026-0027, 0034-0035, and 0065-0067 regarding verifying certificates as part of the process of identifying malicious domains). It would have been obvious prior to the effective filing date of the instant application for Lee to use SAN SSL certificates to determine whether the at least one targeted candidate typosquat domain belongs to a legitimate organization, as using certificate data also allows for one to potentially detect stockpiled domain names before they go live (Szurdi, paragraph 0067, particularly the last sentence thereof). Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Lee [alone or in view of Swype] as applied to claim 1 above, and further in view of “How to Protect Against Domain Squatting” (hereinafter, “Zerofox”). Regarding claim 7: Lee does not explicitly disclose wherein the processor is further configured to: recommend registering the targeted candidate typosquat domains and/or automatically register one or more of the targeted candidate typosquat domains. However, Zerofox discloses as general knowledge in the art that it is recommended to register domains similar to one’s own, including those that are typographic errors thereof, in order to defend against domain squatting (Zerofox, page 8, “How to Protect Against Domain Squatting”, subsection “Register Similar Domain Names”). It would have been immediately obvious prior to the effective filing date of the instant application for the alerts generated by Lee’s invention to at the very least recommend that one should register any of the identified typosquat domains to oneself, as this was clearly a known option for making it more difficult for cyber adversaries to successfully impersonate you or divert traffic away from your website (Zerofox, Ibid). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: U.S. Patent 12,113,828 (Lee)1 U.S. Patent 12,418,558 (Ding) U.S. Patent 7,250,938 (Kirkland) [see Swype Wiki, page 7, “External links”] U.S. Patent 7,098,896 (Kushler) [see Swype Wiki, page 7, “External links”] U.S. Patent Publication 2023/0133524 (Taniguchi) U.S. Patent Publication 2023/0098812 (Rivlin) U.S. Patent Publication 2021/0377303 (Bui) U.S. Patent Publication 2018/0131708 (Pirttilahti) Any inquiry concerning this communication or earlier communications from the examiner should be directed to Thomas A Gyorfi whose telephone number is (571)272-3849. The examiner can normally be reached 10:00am - 6:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. THOMAS A. GYORFI Examiner Art Unit 2435 /THOMAS A GYORFI/Examiner, Art Unit 2435 6/4/2026 1 This is the issued patent resulting from the Lee disclosure cited in the rejections supra.
Read full office action

Prosecution Timeline

Apr 10, 2025
Application Filed
Jun 09, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706952
LARGE LANGUAGE MODEL POWERED SOCIAL INTEGRITY SYSTEM
3y 3m to grant Granted Aug 11, 2026
Patent 12695769
ADAPTIVE SYSTEM FOR NETWORK AND SECURITY MANAGEMENT
3y 1m to grant Granted Jul 28, 2026
Patent 12695786
METHOD AND APPARATUS FOR DDoS ATTACK DETECTION AND MITIGATION IN IoT NETWORK SLICES OF 5G NETWORKS
2y 8m to grant Granted Jul 28, 2026
Patent 12695777
DATA PROCESSING DEVICE, DATA PROCESSING METHOD, AND RECORDING MEDIUM
2y 4m to grant Granted Jul 28, 2026
Patent 12676888
VIRTUAL FILE HONEY POTS FOR COMPUTING SYSTEMS PROTECTION AGAINST RANSOMWARE ATTACKS
2y 9m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
92%
With Interview (+16.3%)
3y 5m (~2y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 699 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month